Act 2017
Law on Tracing Proceeds of Serious Crimes (Money Laundering Act - GwG)
Geldwäschegesetz
Issued by Financial Intelligence Unit (Germany)
Effective: 23 Jun 2017
Last amended: 29 Jun 2026
Plain-English summary
Law on Tracing Proceeds of Serious Crimes, widely referred to by the name of its home country as Geldwäschegesetz (GwG), is the key statutory act of the Federal Republic of Germany that acts as the shield to safeguard the national economy from money laundering, tax evasion, and terrorist financing schemes. Initially adopted by the German Bundestag in 1993 and later revised significantly in 2017, this landmark legislation provides for the transposition of European Union anti-money laundering directives into the domestic legislation. It is a legislation enforced through the rigorous scrutiny of BaFin and Financial Intelligence Unit (FIU) that currently operates and remains in force with its most recent structural revisions effective as of 29 June 2026, adjusting domestic provisions to the European transparency registers. Under the terms of the GwG, all kinds of institutions, including traditional banks, real estate agents, gambling facilities, high-value goods traders, and crypto-asset service providers (CASPs), are mandated to implement adequate AML compliance programs. Among other things, the GwG requires thorough Customer Due Diligence (KYC/CDD) procedures, a 5-year financial trails record retention requirement, and a zero-tolerance approach to Suspicious Transaction Reporting (STR) procedures.
Who it applies to
Banking · NBFC / Non-bank Lending · Crypto / VDA · Real Estate · DNFBPs (Lawyers, Accountants, Dealers)
Topics
AML / CFT / Sanctions
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | FIU-DE | source | |
In Germany, the AML compliance program and officer obligations under the German Money Laundering Act (GwG) and the Banking Act (KWG) entail an obligation that is continuous in nature and is distinguished by a continuous (real-time / daily) time value. The above obligations are mandated in Section 6 and Section 7 of the GwG, as well as the MaRisk circular issued by BaFin, in which all financial and non-financial obliged entities are obligated to create a continuous risk management system. This involves having a continuous risk management system, which entails the appointment of a Money Laundering Reporting Officer (MLRO / Geldwäschebeauftragter) with absolute executive authority to conduct continuous corporate surveillance. In terms of its operation, the continuous tracking is continuous within the organization's environment and consists of performing continuous automated screening of the global asset freezing database, continuous real-time transaction monitoring, and continuous analysis of risks within the organization (Risikoanalyse) to prevent the financial exploitation of the market. The above structural demands are overseen within a two-tiered arrangement by BaFin and Deutsche Bundesbank, where not observing these active daily controls attracts serious administrative penalties. |
||||
| AML record retention | Retention period 5 years | FIU-DE | source | |
According to the German Money Laundering Act (GwG), the Anti-Money Laundering Record Retention requirement is defined strictly as a retention requirement and is regulated by a fixed time period, namely 5 years. This statutory obligation, which has been established according to Section 8 of the GwG and clarified by BaFin, implies that obliged financial and non-financial institutions shall store customer due diligence (KYC), risk assessment, and transaction history in a reliable, unalterable form. In contrast to a general calendar plan, the five-year period will commence at the moment of closing of an account in the case of customer identification records and at the end of the execution year in the case of individual transaction records. The requirement guarantees that a full financial audit trail is entirely organized and available immediately for the BaFin, the Deutsche Bundesbank, the FIU, and the judiciary in the process of a money laundering investigation, irrespective of any GDPR requests for erasing data. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | FIU-DE | source | |
As per the German Money Laundering Act (GwG), the concept of Customer Due Diligence (KYC/CDD) is understood to be an obligation in real-time/daily terms [GwG, MaRisk]. This main compliance requirement, which has been developed pursuant to sections 10 to 15 of the GwG and interpretative guidelines by BaFin, requires that obliged financial and non-financial institutions continuously monitor their customer base rather than performing static identity verification [GwG]. The system functions in real time and ensures that all customer information, transaction patterns, and socio-economic information undergo dynamic monitoring, where automated checks are performed daily against the worldwide sanctions list and PEP database [GwG, MaRisk]. It is also characterized by various risk-based tempos of operation which range from triggering immediate update of data in case of suspicious transactions to conducting periodic reviews in accordance with the risk levels of clients [GwG, MaRisk]. All information must also remain fully auditable by BaFin and the Deutsche Bundesbank. |
||||
| Suspicious transaction reporting | Deadline Immediate | FIU-DE | source | |
In accordance with the German Money Laundering Act (GwG), the Suspicious Transaction Reporting regime refers to an event-based requirement driven by the strict time value of immediate / without delay. The legal requirement, which has been stipulated by Section 43 of the GwG and put in place through the German Financial Intelligence Unit (FIU), requires that as soon as a compliance officer or a Money Laundering Reporting Officer (MLRO) determines the existence of a suspicion that funds or a transaction is associated with money laundering, tax evasion, or terrorist financing, a formal electronic report shall be made immediately through the goAML portal. Contrary to the calendar-based procedure, this requirement shall arise only in response to the occurrence of an irresolvable transaction warning or risky conduct on the part of the client. Practically, the report shall be made before undertaking the transaction to afford the FIU or prosecutors regulatory powers to block or immediately after the execution of the transaction in case there is no absolute block. |
||||
| No obligations match these filters. | ||||
Latest news
-
AUSTRAC Examines Western Union AML Controls and Transaction Monitoring
26 Sep 2026
Australia's financial intelligence unit has initiated a formal investigation into Western Union's anti-money laundering framework and compliance infrastructure. The regulatory examination focuses on the company's paymen…
-
RBI penalizes Ola Financial Services for KYC compliance failures
25 Sep 2026
The Reserve Bank of India imposed a monetary penalty of ₹3.10 lakh on Ola Financial Services Private Limited for non-compliance with KYC directions under the Payment and Settlement Systems Act, 2007. Following a statuto…